THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gmxc-r82q-347r (medium) — libreoffice-convert vulnerable to path traversal / arbitrary file write

[GHSA] GHSA-gmxc-r82q-347r (medium) — libreoffice-convert vulnerable to path traversal / arbitrary file write

medgithub_advisoriesPublished 2026-08-27

GHSA-gmxc-r82q-347r Severity: medium CVE: CVE-2026-54732

libreoffice-convert vulnerable to path traversal / arbitrary file write

### Impact options.fileName is used to build a filesystem path (path.join(tempDir.name, fileName)) and the caller-supplied document buffer is written there, but fileName is never reduced to a base name. A fileName containing "../" escapes the temporary directory, so a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gmxc-r82q-347r